Prb while programaticaly applying an RM policy

Trying to programaticaly apply a policy using LCES web services call, I bump on the following SOAP exception :
com.adobe.edc.sdk.SDKException: Failed to retrieve policy [PS:72238891-845b-4094-88a2-881f532a63ae] -- Invalid policy(error code bin: 1284, hex: 0x504)
The execution context is LCES 8.0.1 SP1b under JBoss with MS Sql Server 2005 database.
Prior to launching the program, we performed the following steps using the LCES adminui web interface under super administrator account :
- Created a domain D
- Created a user U in domain D and assigned him the following roles : 'service user', 'LCRM administrator', 'LCRM End User', 'LCRM Policy Set Administrator', 'LCRM Manage Invited and Local Users', 'LCRM Super Administrator'. No specific group membership has been granted to user U.
- Created a user R in domain D and assigned her the following role : 'LCRM End User'. No specific group membership has been granted to user R.
- Created a new global policy set PS and added domain D during step 2 (visible users and domains). No group or users were defined uring step 3 and 4.
Now, if we take a look at the database, the policy set is registered in the EDCPOLICYSETENTITY table and is not hidden. Looking at the EDCPOLICYSETPRINCIPALENT table, we find the policy set type to be 3 and the principal id to be that of D, as registered in the EDCPRINCIPALDOMAINENTITY table. So far so good. Now we start our program which performs the following steps :
- Under U credentials, register a new policy P in the PS policy set. This step is successful. Using the LCES adminui web interface, we go to Policies list for policy set PS and find our new policy P. Details pane for policy P states the policy ID to be 72238891-845b-4094-88a2-881f532a63ae (same as the one in the error message above).
- Next the program attempts to apply the policy to a PDF document and we encounter the error message stated above.
If we trace LCES server requests to the database, we can observe a failed attempt to retrieve policy set PS in table EDCPOLICYSETPRINCIPALENT. The failure occurs because, LCES search is based on the policy set id AND the associated principal id being one of : user U, GROUP_DOMAINPRINCIPALS for built-in domain EDC_SPECIAL, GROUP_ALLPRINCIPALS, all_authenticated_users, or GROUP_DOMAINPRINCIPALS for domain D. However, as stated above, policy set PS is registered in table EDCPOLICYSETPRINCIPALENT with principal id of domain D.
QUESTIONS :
1°) Is the failed search in table EDCPOLICYSETPRINCIPALENT responsible for the error message we encounter ? If not, what investigation do you suggest ?
2°) If yes, did we forgot some step after creating policy set PS, so that the missed step(s) would lead to at least one row being created in table EDCPOLICYSETPRINCIPALENT that would fulfill the search condition ?

Thank you for your reply Jasmin. In the mean time we figured this out and fixed the problem by updating step 3 and 4 of the policy the same way you suggest it in your answer.
We also wondered for a while about the 5th and 6th parameters of the applyPolicy web method, namely the pubDomain and pubUserName. The LiveCycle ES Java API Reference documentation for the DocumentationManager interface clearly states both or none of them must be set. Sadly, the documentation doesn't highlight another important requirement : the credentials used to invoke the API / web service must be one of a user bound to a role that has been given the 'Identity Impersonation Control' access right. Failing to comply with this additional requirement triggers the following exception when invoking the web service :
com.adobe.edc.sdk.SDKException: Context not authorized with permission : Identity Impersonation Control -- Authentication failed(error code bin: 513, hex: 0x201)

Similar Messages

  • Error while applying the Service Policy

    Hi,
    I am getting the below error while applying the service policy to the Interface.
    I have set the mpls exp 4 as well as want to limit the bandwidth to 1Mbps
    PE#sh policy-map setexp-GBoIP
      Policy Map setexp-GBoIP
        Class GBoIP-traffic
          set mpls experimental imposition 4
         police cir 1024000 bc 32000
           conform-action transmit
           exceed-action drop
    PE(config-if)#int vlan 2007
    PE(config-if)#service-policy input setexp-GBoIP
    QoS-ERROR: Addition/Modification made to policymap setexp-GBoIP and class GBoIP-traffic is not valid, command is rejected
    As well as I have created new clas--map with priority and Bandwidth and applied in output direction, I got the belwo error while applying the Service policy in
    PE(config-if)#service-policy out TEST
    bandwidth command is not supported in output direction for this interface
    PE(config-if)#service-policy output TEST
    priority command is not supported in output direction for this interface
    Any idea why so ?
    Thanks in Advance.
    Regards,
    Nilesh

    Check the current value of IGW_AWARDS_S sequence and make sure the MINVALUE in the patch (i.e. 10000) is not greater than the current one.
    OERR: ORA 4007 MINVALUE cannot be made to exceed the current value (Doc ID 19824.1)
    You may also log a SR.
    Thanks,
    Hussein

  • Applying Software Installation Policy Is Taking Long Time During Boot Process

    1 of my servers is having slow boot up issue. I have enabled user environment debugging and the gpsvc.log file has been generated. I have also used the Windows Performance Analyzer to capture logs and results came back that the GP Client is taking a long
    time in the boot process. So, I reckoned the slow boot is due to GPO but I am not sure where to look from this log file.
    I have only paste part of the gpsvc.log file here due to limitation in the number of characters allowed to be posted. Would appreciate some good advise on this issue that I am facing.
    GPSVC(34c.408) 04:03:30:109 ReadExtStatus: Reading Previous Status for extension {FB2CA36D-0B40-4307-821B-A13B252DE56C}
    GPSVC(34c.408) 04:03:30:109 ReadExtStatus: Reading Previous Status for extension {fbf687e6-f063-4d9f-9f4f-fd9a26acdd5f}
    GPSVC(34c.408) 04:03:30:109 GetMachineToken:  Looping for authentication again.
    GPSVC(34c.408) 04:03:30:109 ProcessGPOs: Logging Data for Target <SW01E772>.
    GPSVC(34c.408) 04:03:30:109 GPLockPolicySection: Sid = (null), dwTimeout= 30000, dwFlags= 0
    GPSVC(34c.408) 04:03:30:109 LockPolicySectioncalled for user <Machine>
    GPSVC(34c.408) 04:03:30:109 Sync Lock Called
    GPSVC(34c.408) 04:03:30:109 Writer Lock got immediately.
    GPSVC(34c.408) 04:03:30:109 Lock taken successfully
    GPSVC(34c.408) 04:03:30:109 UnLockPolicySectioncalled for user <Machine>
    GPSVC(34c.408) 04:03:30:109 UnLockedsuccessfully
    GPSVC(34c.408) 04:03:30:109 ProcessGPOs: OpenThreadTokenfailed with error 1008, assuming thread is not impersonating
    GPSVC(34c.408) 04:03:30:109 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:30:109 ProcessGPOs: Processing extension Registry
    GPSVC(34c.408) 04:03:30:125 ReadStatus: Read Extension's Previous status successfully.
    GPSVC(34c.408) 04:03:30:125 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:30:125 CheckGPOs: No GPO changes and nosecurity group membership change and extension Registry has NoGPOChangesset.
    GPSVC(34c.408) 04:03:30:125 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:30:125 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:30:125 ProcessGPOs: Processing extension Wireless Group Policy
    GPSVC(34c.408) 04:03:30:125CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:30:125 CheckGPOs: No GPO changes but couldn't read extension Wireless Group Policy's status or policy time.
    GPSVC(34c.408) 04:03:30:125 ProcessGPOs: Extension Wireless Group Policy skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:30:125 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:30:125 ProcessGPOs: Processing extension Group Policy Environment
    GPSVC(34c.408) 04:03:30:125 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:30:125 CheckGPOs: No GPO changes but couldn't read extension Group Policy Environment's status or policy time.
    GPSVC(34c.408) 04:03:30:125 ProcessGPOs: Extension Group Policy Environment skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:30:125 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:30:125 ProcessGPOs: Processing extension Group Policy Local Users and Groups
    GPSVC(34c.408) 04:03:30:125 ReadStatus: Read Extension's Previous status successfully.
    GPSVC(34c.408) 04:03:30:125 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:30:156 GPLockPolicySection: Sid = (null), dwTimeout= 30000, dwFlags= 0
    GPSVC(34c.408) 04:03:30:156 LockPolicySectioncalled for user <Machine>
    GPSVC(34c.408) 04:03:30:156 Sync Lock Called
    GPSVC(34c.408)04:03:30:156 Writer Lock got immediately.
    GPSVC(34c.408) 04:03:30:156 Lock taken successfully
    GPSVC(34c.408) 04:03:30:156 ProcessGPOList: Entering for extension Group Policy Local Users and Groups
    GPSVC(34c.408) 04:03:30:156 MachinePolicyCallback: Settingstatus UI to Applying Group Policy Local Users and Groups policy...
    GPSVC(34c.408) 04:03:30:156 ProcessGPOList: No changes. CSEwill not be passed in the IwbemServicesintfptr
    GPSVC(34c.364)04:03:30:156 Message Status = <Applying Group Policy Local Users and Groups policy...>
    GPSVC(34c.364) 04:03:30:156 Setting GPsessionstate = 1
    GPSVC(34c.408) 04:03:31:796 ProcessGroupPolicyCompletedExInternal: Entering. Extension = {17D89FEC-5C44-4972-B12D-241CAEF74509}, dwStatus= 0x0
    GPSVC(34c.408) 04:03:31:953 GetWbemServices: CoCreateInstancesucceeded
    GPSVC(34c.408) 04:03:36:031 ConnectToNameSpace: ConnectServerreturned 0x0
    GPSVC(34c.408) 04:03:36:140 ProcessGroupPolicyCompletedExInternal: Extension {17D89FEC-5C44-4972-B12D-241CAEF74509} was able to log data. Error = 0x0, dwRet= 0. Clearing the dirty bit
    GPSVC(34c.408) 04:03:36:500 ProcessGroupPolicyCompletedExInternal: Finished processing extension <Group Policy Local Users and Groups> at 44203 ticks (ms)
    GPSVC(34c.408) 04:03:36:500 ProcessGroupPolicyCompletedExInternal: Leaving. Extension = {17D89FEC-5C44-4972-B12D-241CAEF74509}, Return status dwRet= 0x0
    GPSVC(34c.408) 04:03:36:500 ProcessGPOList: Extension Group Policy Local Users and Groups returned 0x0.
    GPSVC(34c.408) 04:03:36:500 ProcessGPOList: Extension Group Policy Local Users and Groups status was not updated because there was no changes and no transition or rsopwasn't enabled
    GPSVC(34c.408) 04:03:36:500 UnLockPolicySectioncalled for user <Machine>
    GPSVC(34c.408) 04:03:36:500 UnLockedsuccessfully
    GPSVC(34c.408) 04:03:36:531 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:531 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:531 ProcessGPOs: Processing extension Group Policy Device Settings
    GPSVC(34c.408) 04:03:36:531 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:531 CheckGPOs: No GPO changes but couldn't read extension Group Policy Device Settings'sstatus or policy time.
    GPSVC(34c.408) 04:03:36:531 ProcessGPOs: Extension Group Policy Device Settings skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:36:531 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:531 ProcessGPOs: Processing extension Folder Redirection
    GPSVC(34c.408) 04:03:36:531 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:531 CheckGPOs: No GPO changes but couldn't read extension Folder Redirection's status or policy time.
    GPSVC(34c.408) 04:03:36:531 ProcessGPOs: Extension Folder Redirection skipped with flags 0x7.
    GPSVC(34c.408) 04:03:36:531 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:531 ProcessGPOs: Processing extension Microsoft Disk Quota
    GPSVC(34c.408) 04:03:36:531 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:531 CheckGPOs: No GPO changes but couldn't read extension Microsoft Disk Quota's status or policy time.
    GPSVC(34c.408) 04:03:36:531 ProcessGPOs: Extension Microsoft Disk Quota skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:36:531 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:531 ProcessGPOs: Processing extension Group Policy Network Options
    GPSVC(34c.408) 04:03:36:531CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:546 CheckGPOs: No GPO changes but couldn't read extension Group Policy Network Options'sstatus or policy time.
    GPSVC(34c.408) 04:03:36:546 ProcessGPOs: Extension Group Policy Network Options skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:36:546 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:546 ProcessGPOs: Processing extension QoSPacket Scheduler
    GPSVC(34c.408) 04:03:36:546 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:546 CheckGPOs: No GPO changes but couldn't read extension QoSPacket Scheduler's status or policy time.
    GPSVC(34c.408) 04:03:36:546 ProcessGPOs: Extension QoSPacket Scheduler skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:36:546 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:546 ProcessGPOs: Processing extension Scripts
    GPSVC(34c.408) 04:03:36:546 ReadStatus: Read Extension's Previous status successfully.
    GPSVC(34c.408) 04:03:36:546 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:546 CheckGPOs: No GPO changes and no security group membership change and extension Scripts has NoGPOChangesset.
    GPSVC(34c.408) 04:03:36:546 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:546 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:546 ProcessGPOs: Processing extension Remote Desktop USB Redirection
    GPSVC(34c.408) 04:03:36:546 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:546 CheckGPOs: No GPO changes but couldn't read extension Remote Desktop USB Redirection's status or policy time.
    GPSVC(34c.408) 04:03:36:546 ProcessGPOs: Extension Remote Desktop USB Redirection skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:36:546 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:546 ProcessGPOs: Processing extension Internet Explorer Zonemapping
    GPSVC(34c.408) 04:03:36:562 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:562 CheckGPOs: No GPO changes but couldn't read extension Internet Explorer Zonemapping'sstatus or policy time.
    GPSVC(34c.408) 04:03:36:562 ProcessGPOs: Extension Internet Explorer Zonemappingskipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:36:562 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:562 ProcessGPOs: Processing extension Group Policy Drive Maps
    GPSVC(34c.408) 04:03:36:562 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:562 CheckGPOs: No GPO changes but couldn't read extension Group Policy Drive Maps'sstatus or policy time.
    GPSVC(34c.408) 04:03:36:562 ProcessGPOs: Extension Group Policy Drive Maps skipped withflags 0x7.
    GPSVC(34c.408) 04:03:36:562 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:562 ProcessGPOs: Processingextension Group Policy Folders
    GPSVC(34c.408) 04:03:36:562 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:562 CheckGPOs: No GPO changes but couldn't read extension Group Policy Folders'sstatus or policy time.
    GPSVC(34c.408) 04:03:36:562 ProcessGPOs: Extension Group Policy Folders skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:36:562 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:562 ProcessGPOs: Processing extension Group Policy Network Shares
    GPSVC(34c.408) 04:03:36:562 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:562 CheckGPOs: No GPO changes but couldn't read extension Group Policy Network Shares's status or policy time.
    GPSVC(34c.408) 04:03:36:562 ProcessGPOs: Extension Group Policy Network Shares skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:36:562 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:562 ProcessGPOs: Processing extension Group Policy Files
    GPSVC(34c.408) 04:03:36:562 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:562 CheckGPOs: No GPO changes but couldn't readextension Group Policy Files's status or policy time.
    GPSVC(34c.408) 04:03:36:562 ProcessGPOs: Extension Group Policy Files skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:36:562 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:562 ProcessGPOs: Processing extension Group Policy Data Sources
    GPSVC(34c.408) 04:03:36:562 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:578 CheckGPOs:No GPO changes but couldn't read extension Group Policy Data Sources's status or policy time.
    GPSVC(34c.408) 04:03:36:578 ProcessGPOs: Extension Group Policy Data Sources skipped because bothdeleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:36:578 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:578 ProcessGPOs: Processing extension Group Policy Ini Files
    GPSVC(34c.408) 04:03:36:578 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:578 CheckGPOs: No GPO changes but couldn't read extension Group Policy Ini Files's status or policy time.
    GPSVC(34c.408) 04:03:36:578 ProcessGPOs: Extension GroupPolicy Ini Files skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:36:578 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:578 ProcessGPOs: Processing extension Internet Explorer User Accelerators
    GPSVC(34c.408) 04:03:36:578 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:578 CheckGPOs: No GPO changes but couldn't readextension Internet Explorer User Accelerators's status or policy time.
    GPSVC(34c.408) 04:03:36:578 ProcessGPOs: Extension Internet Explorer User Accelerators skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:36:578 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:578 ProcessGPOs: Processing extension Security
    GPSVC(34c.408) 04:03:36:578ReadStatus: Read Extension's Previous status successfully.
    GPSVC(34c.408) 04:03:36:578 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:578 CheckGPOs: No GPO changes and no security group membership change and extension Security has NoGPOChanges set.
    GPSVC(34c.408) 04:03:36:578 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:578 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:578 ProcessGPOs: Processing extension Deployed Printer Connections
    GPSVC(34c.408) 04:03:36:578 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:578 CheckGPOs: No GPO changes but couldn't read extension Deployed Printer Connections's status or policy time.
    GPSVC(34c.408) 04:03:36:578 ProcessGPOs: Extension Deployed Printer Connections skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:36:578 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:593 ProcessGPOs: Processing extension Group Policy Services
    GPSVC(34c.408) 04:03:36:593 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:593 CheckGPOs: No GPO changes but couldn't read extension Group Policy Services's status or policy time.
    GPSVC(34c.408) 04:03:36:593 ProcessGPOs: Extension Group Policy Services skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:36:593 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:593 ProcessGPOs: Processing extension Internet Explorer Branding
    GPSVC(34c.408) 04:03:36:593 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:593 CheckGPOs: No GPO changes but couldn't read extension Internet Explorer Branding's status or policy time.
    GPSVC(34c.408) 04:03:36:593 ProcessGPOs: Extension Internet Explorer Branding skipped with flags 0x7.
    GPSVC(34c.408) 04:03:36:593 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:593 ProcessGPOs: Processing extension Group PolicyFolder Options
    GPSVC(34c.408) 04:03:36:593 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:593 CheckGPOs: No GPO changes but couldn't read extension Group Policy Folder Options's status or policy time.
    GPSVC(34c.408) 04:03:36:593 ProcessGPOs: Extension Group Policy Folder Options skipped because bothdeleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:36:593 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:593 ProcessGPOs: Processing extension Group Policy Scheduled Tasks
    GPSVC(34c.408) 04:03:36:593 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:593 CheckGPOs: No GPO changes but couldn't read extension Group Policy Scheduled Tasks's status or policy time.
    GPSVC(34c.408) 04:03:36:593 ProcessGPOs: Extension Group Policy Scheduled Tasks skipped because both deletedand changed GPO lists are empty.
    GPSVC(34c.408) 04:03:36:593 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:593 ProcessGPOs: Processing extension Group Policy Registry
    GPSVC(34c.408) 04:03:36:593 ReadStatus: Read Extension's Previous status successfully.
    GPSVC(34c.408) 04:03:36:593 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:625 GPLockPolicySection: Sid = (null), dwTimeout = 30000, dwFlags = 0
    GPSVC(34c.408)04:03:36:625 LockPolicySection called for user <Machine>
    GPSVC(34c.408) 04:03:36:625 Sync Lock Called
    GPSVC(34c.408) 04:03:36:625 Writer Lock got immediately.
    GPSVC(34c.408) 04:03:36:625 Locktaken successfully
    GPSVC(34c.408) 04:03:36:625 ProcessGPOList: Entering for extension Group Policy Registry
    GPSVC(34c.408) 04:03:36:625 MachinePolicyCallback: Setting status UI to Applying Group Policy Registry policy...
    GPSVC(34c.408) 04:03:36:625 ProcessGPOList: No changes. CSE will not be passed in the IwbemServices intf ptr
    GPSVC(34c.364) 04:03:36:625 Setting GPsession state =1
    GPSVC(34c.408) 04:03:36:765 ProcessGroupPolicyCompletedExInternal: Entering. Extension = {B087BE9D-ED37-454F-AF9C-04291E351182}, dwStatus = 0x0
    GPSVC(34c.408) 04:03:36:796 GetWbemServices: CoCreateInstance succeeded
    GPSVC(34c.408) 04:03:36:812 ConnectToNameSpace: ConnectServer returned 0x0
    GPSVC(34c.408) 04:03:36:812 ProcessGroupPolicyCompletedExInternal: Extension {B087BE9D-ED37-454F-AF9C-04291E351182} was able to log data. Error = 0x0, dwRet = 0. Clearing the dirty bit
    GPSVC(34c.408) 04:03:36:843 ProcessGroupPolicyCompletedExInternal: Finished processing extension <Group Policy Registry> at 44546 ticks (ms)
    GPSVC(34c.408) 04:03:36:843 ProcessGroupPolicyCompletedExInternal: Leaving. Extension = {B087BE9D-ED37-454F-AF9C-04291E351182}, Return status dwRet = 0x0
    GPSVC(34c.408) 04:03:36:843 ProcessGPOList: Extension Group Policy Registry returned 0x0.
    GPSVC(34c.408) 04:03:36:843 ProcessGPOList: Extension Group Policy Registry status was not updated because there was no changes and no transition or rsop wasn'tenabled
    GPSVC(34c.408) 04:03:36:843 UnLockPolicySection called for user <Machine>
    GPSVC(34c.408) 04:03:36:843 UnLocked successfully
    GPSVC(34c.408) 04:03:36:875 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:875 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:875 ProcessGPOs: Processing extension 802.3 Group Policy
    GPSVC(34c.408) 04:03:36:875 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:875 CheckGPOs: No GPO changes but couldn't read extension 802.3 Group Policy's status or policy time.
    GPSVC(34c.408) 04:03:36:875 ProcessGPOs: Extension 802.3 Group Policy skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:36:875 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:875 ProcessGPOs: Processing extension Group Policy Printers
    GPSVC(34c.408) 04:03:36:875 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:875 CheckGPOs: No GPO changes but couldn't read extension Group Policy Printers's status or policy time.
    GPSVC(34c.408) 04:03:36:875 ProcessGPOs: Extension Group Policy Printers skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:36:875 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:875 ProcessGPOs: Processing extension Group Policy Shortcuts
    GPSVC(34c.408) 04:03:36:875 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:875 CheckGPOs: No GPO changes but couldn't read extension Group Policy Shortcuts's status or policy time.
    GPSVC(34c.408) 04:03:36:875 ProcessGPOs: Extension Group Policy Shortcuts skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:36:875 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:36:890 ProcessGPOs: Processing extension Software Installation
    GPSVC(34c.408) 04:03:36:890 ReadStatus: Read Extension's Previous status successfully.
    GPSVC(34c.408) 04:03:36:890 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:36:890 GPLockPolicySection: Sid = (null), dwTimeout = 30000, dwFlags = 0
    GPSVC(34c.408) 04:03:36:890 LockPolicySection called for user <Machine>
    GPSVC(34c.408) 04:03:36:890 Sync Lock Called
    GPSVC(34c.408) 04:03:36:890 Writer Lock got immediately.
    GPSVC(34c.408) 04:03:36:890 Lock taken successfully
    GPSVC(34c.408) 04:03:36:890 ProcessGPOList: Entering for extension Software Installation
    GPSVC(34c.408) 04:03:36:890 MachinePolicyCallback: Setting status UI to Applying Software Installation policy...
    GPSVC(34c.408) 04:03:36:890ProcessGPOList: No changes. CSE will not be passed in the IwbemServices intf ptr
    GPSVC(34c.364) 04:03:36:890 Message Status = <Applying Software Installation policy...>
    GPSVC(34c.364) 04:03:36:890 Setting GPsession state = 1
    GPSVC(34c.408) 04:03:37:312 ProcessGPOList: Extension Software Installation returned 0x0.
    GPSVC(34c.408) 04:03:37:312 ProcessGPOList: Extension Software Installation status was not updated because there was no changes and no transition or rsop wasn't enabled
    GPSVC(34c.408) 04:03:37:312UnLockPolicySection called for user <Machine>
    GPSVC(34c.408) 04:03:37:312 UnLocked successfully
    GPSVC(34c.408) 04:03:37:328 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:37:328 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:37:328 ProcessGPOs: Processing extension TCPIP
    GPSVC(34c.408) 04:03:37:328 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:37:328 CheckGPOs: No GPO changes but couldn't read extension TCPIP's status or policy time.
    GPSVC(34c.408) 04:03:37:328 ProcessGPOs: Extension TCPIP skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:37:328 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:37:328 ProcessGPOs: Processing extension Internet Explorer Machine Accelerators
    GPSVC(34c.408) 04:03:37:328 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:37:328 CheckGPOs: No GPO changes but couldn't read extension Internet Explorer Machine Accelerators's status or policy time.
    GPSVC(34c.408) 04:03:37:328 ProcessGPOs: Extension Internet Explorer Machine Accelerators skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:37:328 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:37:328 ProcessGPOs: Processing extension IP Security
    GPSVC(34c.408) 04:03:37:328 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:37:328 CheckGPOs: No GPO changes but couldn't read extension IP Security's status or policy time.
    GPSVC(34c.408) 04:03:37:328 ProcessGPOs: Extension IP Security skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:37:328 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:37:328 ProcessGPOs: Processing extension Group Policy Internet Settings
    GPSVC(34c.408) 04:03:37:343 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:37:343 CheckGPOs: No GPO changes but couldn't read extension Group Policy Internet Settings's status or policy time.
    GPSVC(34c.408) 04:03:37:343 ProcessGPOs: Extension Group Policy Internet Settings skipped with flags 0x7.
    GPSVC(34c.408) 04:03:37:343 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:37:343 ProcessGPOs: Processing extension Group Policy Start Menu Settings
    GPSVC(34c.408) 04:03:37:343 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:37:343 CheckGPOs: No GPO changes but couldn't read extension Group Policy Start Menu Settings's status or policy time.
    GPSVC(34c.408) 04:03:37:343 ProcessGPOs: Extension Group Policy Start Menu Settings skipped because both deleted and changed GPO listsare empty.
    GPSVC(34c.408) 04:03:37:343 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:37:343 ProcessGPOs: Processingextension Group Policy Regional Options
    GPSVC(34c.408) 04:03:37:343 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:37:343 CheckGPOs: No GPO changes but couldn't read extensionGroup Policy Regional Options's status or policy time.
    GPSVC(34c.408) 04:03:37:343 ProcessGPOs: Extension Group Policy RegionalOptions skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:37:343 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:37:343 ProcessGPOs: Processing extension Group Policy Power Options
    GPSVC(34c.408) 04:03:37:343 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:37:343 CheckGPOs: No GPO changes but couldn't read extension Group Policy Power Options's status or policy time.
    GPSVC(34c.408) 04:03:37:343 ProcessGPOs: Extension Group Policy Power Options skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:37:343 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:37:343 ProcessGPOs: Processing extension Audit Policy Configuration
    GPSVC(34c.408) 04:03:37:343 CompareGPOLists: The lists are the same.
    GPSVC(34c.408) 04:03:37:343 CheckGPOs: No GPO changes but couldn't read extension Audit Policy Configuration's status or policy time.
    GPSVC(34c.408) 04:03:37:343 ProcessGPOs: Extension Audit Policy Configuration skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:37:343 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:37:343 ProcessGPOs: Processing extension Group Policy Applications
    GPSVC(34c.408) 04:03:37:359 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:37:359 CheckGPOs: No GPO changes but couldn't read extension Group Policy Applications's status or policy time.
    GPSVC(34c.408) 04:03:37:359 ProcessGPOs: Extension Group Policy Applications skipped with flags 0x7.
    GPSVC(34c.408) 04:03:37:359 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:37:359 ProcessGPOs: Processing extension Enterprise QoS
    GPSVC(34c.408) 04:03:37:359 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:37:359 CheckGPOs: No GPO changes but couldn't read extension Enterprise QoS's status or policy time.
    GPSVC(34c.408) 04:03:37:359 ProcessGPOs: Extension Enterprise QoS skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:37:359 ProcessGPOs: -----------------------
    GPSVC(34c.408) 04:03:37:359 ProcessGPOs: Processing extensionCP
    GPSVC(34c.408) 04:03:37:359 CompareGPOLists:  The lists are the same.
    GPSVC(34c.408) 04:03:37:359 CheckGPOs: No GPO changes but couldn't read extension CP's status or policy time.
    GPSVC(34c.408) 04:03:37:359 ProcessGPOs: Extension CP skipped because both deleted and changed GPO lists are empty.
    GPSVC(34c.408) 04:03:37:359 gpGetFgPolicyRefreshInfo: Mode: 1, Reason: 7
    GPSVC(34c.408) 04:03:37:359 SetFgRefreshInfo: Previous Machine Fg policy Synchronous, Reason: SKU.
    GPSVC(34c.408) 04:03:37:359 SetFgRefreshInfo: Next Machine Fg policy Synchronous, Reason: SKU.
    GPSVC(34c.408) 04:03:37:359 ProcessGPOs: No WMI logging done in this policy cycle.
    GPSVC(34c.408) 04:03:37:359 ProcessGPOs: Boot/Logon Policy processing - checking if UBPM trigger events need to be fired
    GPSVC(34c.408) 04:03:37:375 CheckAndFireGPTriggerEvent: FiredPolicy present UBPM trigger event for Machine.
    GPSVC(34c.408) 04:03:37:375 Application complete with bConnectivityFailure = 0.
    GPSVC(34c.79c) 04:03:40:546 CGPNotify::RegisterForNotification: Entering with target Machine and event 0xc8c
    GPSVC(34c.79c) 04:03:40:546 Client_InitialRegisterForNotification: User = machine, changenumber = 0
    GPSVC(34c.3a0) 04:03:40:546 Target = Machine
    GPSVC(34c.79c) 04:03:40:546 Client_RegisterForNotification: User =machine, changenumber = 0
    GPSVC(34c.79c) 04:03:40:546 CGPNotify::RegisterForNotification: Exiting with status = 0
    GPSVC(3bc.ac8) 04:03:59:296 CGPNotify::RegisterForNotification: Entering withtarget Machine and event 0x1ac
    GPSVC(3bc.ac8) 04:03:59:296 Client_InitialRegisterForNotification: User = machine, changenumber = 0
    GPSVC(34c.748) 04:03:59:296 Target = Machine
    GPSVC(3bc.ac8) 04:03:59:296 Client_RegisterForNotification: User = machine, changenumber = 0
    GPSVC(3bc.ac8) 04:03:59:296 CGPNotify::RegisterForNotification: Exiting with status = 0
    GPSVC(34c.748) 04:03:59:343 Target = Machine
    GPSVC(34c.748) 04:03:59:343 Target = Machine,ChangeNumber 0
    GPSVC(34c.3ac) 04:03:59:515 Target = Machine
    GPSVC(34c.3ac) 04:03:59:531 Target = Machine, ChangeNumber 0
    GPSVC(34c.3ac) 04:03:59:531 Sid = (null), dwTimeout = 600000, dwFlags = 268435456
    GPSVC(34c.3ac) 04:03:59:531 LockPolicySection calledfor user <Machine>
    GPSVC(34c.3ac) 04:03:59:546 Async Lock called
    GPSVC(34c.3ac) 04:03:59:546 Reader Lock got immediately. m_cReadersInLock : 1
    GPSVC(34c.3ac) 04:03:59:546 Sid = (null)
    GPSVC(34c.3ac) 04:03:59:546 UnLockPolicySection called for user <Machine>
    GPSVC(34c.3ac) 04:03:59:546 Found the caller in the ReaderHavingLock List. Removing it...
    GPSVC(34c.3ac) 04:03:59:546 Settinglock state as notLocked
    GPSVC(34c.3ac) 04:03:59:546 UnLocked successfully
    GPSVC(34c.bdc) 04:04:00:000 CGPNotify::RegisterForNotification: Entering with target Machine and event 0xd04
    GPSVC(34c.bdc) 04:04:00:000 Client_InitialRegisterForNotification: User = machine, changenumber = 0
    GPSVC(34c.3ac) 04:04:00:000 Target =Machine
    GPSVC(34c.bdc) 04:04:00:000 Client_RegisterForNotification: User = machine, changenumber = 0
    GPSVC(34c.bdc) 04:04:00:000 CGPNotify::RegisterForNotification: Exiting with status = 0
    GPSVC(34c.3ac) 04:04:00:000 Target = Machine, ChangeNumber 0
    GPSVC(34c.748) 04:04:01:140 Target = Machine
    GPSVC(34c.748) 04:04:01:140 Target = Machine, ChangeNumber 0
    GPSVC(154.41c) 04:05:25:509CGPNotify::RegisterForNotification: Entering with target Machine and event 0x458
    GPSVC(154.41c) 04:05:25:509 Client_InitialRegisterForNotification: User = machine, changenumber = 0
    GPSVC(34c.3ac) 04:05:25:509 Target = Machine
    GPSVC(154.41c) 04:05:25:525 Client_RegisterForNotification: User = machine, changenumber = 0
    GPSVC(34c.3ac) 04:05:25:525 Target = Machine, ChangeNumber 0
    GPSVC(154.41c) 04:05:25:525 CGPNotify::RegisterForNotification: Exiting with status = 0
    GPSVC(154.41c) 04:05:25:759 CGPNotify::RegisterForNotification: Entering with target Machine and event 0x4e8
    GPSVC(154.41c) 04:05:25:759 Client_InitialRegisterForNotification: User = machine, changenumber = 0
    GPSVC(34c.3ac) 04:05:25:759 Target = Machine
    GPSVC(154.41c) 04:05:25:775 Client_RegisterForNotification: User = machine, changenumber = 0
    GPSVC(154.41c) 04:05:25:775 CGPNotify::RegisterForNotification: Exiting with status = 0
    GPSVC(34c.3ac) 04:05:25:775 Target = Machine, ChangeNumber 0
    GPSVC(34c.3ac) 04:05:59:217 Target = Machine
    GPSVC(34c.3ac)04:05:59:233 Target = Machine, ChangeNumber 0
    GPSVC(3bc.3cc) 04:05:59:389 CGPNotify::UnregisterNotification: Entering with event 0x1ac
    GPSVC(3bc.3cc) 04:05:59:389 CGPNotify::AbortAsyncRegistration: No asyn registration is pending
    GPSVC(3bc.3cc) 04:05:59:405 CGPNotify::UnregisterNotification: Canceling pending calls
    GPSVC(3bc.3cc) 04:05:59:420 Client_CompleteNotificationCall: failed with 0x4c7
    GPSVC(3bc.3cc) 04:05:59:420 CGPNotify::UnregisterNotification: Cancelled pending calls
    GPSVC(3bc.3cc) 04:05:59:420 CGPNotify::UnregisterNotification: Exiting with dwStatus = 0x0
    GPSVC(34c.360) 04:06:00:827 Target = Machine
    GPSVC(34c.360) 04:06:00:827 Target = Machine, ChangeNumber 0
    GPSVC(34c.360) 04:06:01:155 Target = Machine
    GPSVC(34c.360) 04:06:01:171 Target = Machine, ChangeNumber 0
    GPSVC(34c.fe8) 04:06:02:124 CGPNotify::RegisterForNotification: Entering with target Machine and event 0x218
    GPSVC(34c.fe8) 04:06:02:140 Client_InitialRegisterForNotification: User = machine, changenumber = 0
    GPSVC(34c.360) 04:06:02:155 Target = Machine
    GPSVC(34c.fe8) 04:06:02:155 Client_RegisterForNotification: User = machine, changenumber = 0
    GPSVC(34c.fe8) 04:06:02:171 CGPNotify::RegisterForNotification: Exiting with status = 0
    GPSVC(34c.da4) 05:06:16:856 Target = Machine
    GPSVC(34c.da4) 05:06:16:856 Target = Machine, ChangeNumber 0
    GPSVC(34c.da4) 05:06:16:856 Target = S-1-5-20
    GPSVC(34c.da4) 05:06:16:856 Could not find user by sid, finding user by session id
    GPSVC(34c.da4) 05:06:16:856 Caller requesting for user notification/lock is from session 0
    GPSVC(34c.da4) 05:06:16:856 Target = S-1-5-20, ChangeNumber 0
    GPSVC(34c.da4) 05:06:16:856 Could not find user by sid, finding user by session id
    GPSVC(34c.de8) 05:06:16:856 Target = S-1-5-20
    GPSVC(34c.de8) 05:06:16:856 Could not find user by sid, finding user by session id
    GPSVC(34c.de8) 05:06:16:872 Callerrequesting for user notification/lock is from session 0
    GPSVC(34c.de8) 05:06:16:872 Target = S-1-5-20, ChangeNumber 0
    GPSVC(34c.de8) 05:06:16:872 Could not find user by sid, finding user by session id
    GPSVC(34c.de8) 05:06:16:872 Caller requesting for usernotification/lock is from session 0
    GPSVC(34c.da4) 05:06:16:872Target = S-1-5-20
    GPSVC(34c.da4) 05:06:16:872 Could not find user by sid, finding user by session id
    GPSVC(34c.da4) 05:06:16:872 Caller requesting for user notification/lock is from session 0
    GPSVC(34c.da4) 05:06:16:872 Target = S-1-5-20, ChangeNumber 0
    GPSVC(34c.da4) 05:06:16:872 Could not find user by sid, finding user by session id
    GPSVC(34c.da4) 05:06:16:872 Caller requesting for user notification/lock is from session 0
    GPSVC(34c.de8) 05:06:16:887 Target = S-1-5-20
    GPSVC(34c.de8) 05:06:16:887 Could notfind user by sid, finding user by session id
    GPSVC(34c.de8) 05:06:16:887 Caller requesting for user notification/lock is from session 0
    GPSVC(34c.de8) 05:06:16:887 Target = S-1-5-20, ChangeNumber 0
    GPSVC(34c.de8) 05:06:16:887 Could not find user by sid, finding user by session id
    GPSVC(34c.de8) 05:06:16:887 Caller requesting for user notification/lock is from session 0
    GPSVC(34c.da4) 05:06:26:981 Setting GPsession state = 1
    GPSVC(34c.de8) 05:06:32:341 SID = S-1-5-21-206128196-3657029889-627342018-7757
    GPSVC(34c.de8) 05:06:32:356 bMachine = 0
    GPSVC(34c.de8) 05:06:32:356 Setting GPsession state = 1
    GPSVC(34c.de8) 05:06:32:356 Message Status = <Applying user settings...>
    GPSVC(34c.778) 05:06:32:356 StartTime For network wait: 32140ms
    GPSVC(34c.778) 05:06:32:356 Current Time: 3819953ms
    GPSVC(34c.de8) 05:06:32:356 Setting GPsession state = 1
    GPSVC(34c.778) 05:06:32:356 MaxTimeToWaitForNetwork: 5212ms
    GPSVC(34c.778) 05:06:32:356 TimeRemainingToWaitForNetwork: 0ms
    GPSVC(34c.778) 05:06:32:356 UserPolicy: Waiting for machine policy wait for network event with timeout 0 ms
    GPSVC(34c.778) 05:06:32:388 GPLockPolicySection: Sid = (null), dwTimeout = 30000, dwFlags = 65538
    GPSVC(34c.778) 05:06:32:388 LockPolicySection called for user <Machine>

    Hi,
    Any update?
    Just checking in to see if the suggestions were helpful. Please let us know if you would like further assistance.
    Best Regards,
    Andy Qi
    TechNet Subscriber Support
    If you are
    TechNet Subscription user and have any feedback on our support quality, please send your feedback
    here.
    Andy Qi
    TechNet Community Support

  • Event ID 1085 on DC - Failed to Apply the Group Policy Local Users and Groups Settings

    I have a domain with 2 DCs.  The primary DC is running Server 2012 and is raising Event ID 1085 every 10 minutes and 20 seconds.
    Windows failed to apply the Group Policy Local Users and Groups settings. Group Policy Local Users and Groups settings might have its own log file. Please click on the "More information" link.
    System
    - Provider
    [ Name] Microsoft-Windows-GroupPolicy
    [ Guid] {AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}
    EventID 1085
    Version 0
    Level 3
    Task 0
    Opcode 1
    Keywords 0x8000000000000000
    - TimeCreated
    [ SystemTime] 2014-10-20T20:09:03.706992400Z
    EventRecordID 130087
    - Correlation
    [ ActivityID] {FDDFB8C5-9ECF-41B9-B2B4-3AD0B345A37A}
    - Execution
    [ ProcessID] 1000
    [ ThreadID] 3280
    Channel System
    Computer SERVER.DOMAIN.NAME
    - Security
    [ UserID] S-1-5-18
    - EventData
    SupportInfo1 1
    SupportInfo2 4404
    ProcessingMode 0
    ProcessingTimeInMilliseconds 10343
    ErrorCode 183
    ErrorDescription Cannot create a file when that file already exists.
    DCName \\SERVER.DOMAIN.name
    ExtensionName Group Policy Local Users and Groups
    ExtensionId {17D89FEC-5C44-4972-B12D-241CAEF74509}
    Everything I look up for Event ID 1085 seems to be about a different cause.
    Any ideas?

    I enabled tracing on a domain gpo and I still get the error when running gpupdate /force .
    I'm also still getting Event 1085.  Here's the trace file.  I've anonymized the site/domain and the GUIDs.
    2014-10-21 11:16:54.003 [pid=0x3e8,tid=0xcd0] Entering ProcessGroupPolicyExLocUsAndGroups()
    2014-10-21 11:16:54.018 [pid=0x3e8,tid=0xcd0] SOFTWARE\Policies\Microsoft\Windows\Group Policy\{GUID-1}
    2014-10-21 11:16:54.018 [pid=0x3e8,tid=0xcd0] BackgroundPriorityLevel ( 0 )
    2014-10-21 11:16:54.018 [pid=0x3e8,tid=0xcd0] DisableRSoP ( 0 )
    2014-10-21 11:16:54.018 [pid=0x3e8,tid=0xcd0] LogLevel ( 2 )
    2014-10-21 11:16:54.018 [pid=0x3e8,tid=0xcd0] Command subsystem initialized. [SUCCEEDED(S_FALSE)]
    2014-10-21 11:16:54.065 [pid=0x3e8,tid=0xcd0] Background priority set to 0 (Idle).
    2014-10-21 11:16:54.065 [pid=0x3e8,tid=0xcd0] ----- Parameters
    2014-10-21 11:16:54.065 [pid=0x3e8,tid=0xcd0] CSE GUID : {GUID-1}
    2014-10-21 11:16:54.065 [pid=0x3e8,tid=0xcd0] Flags : ( X ) GPO_INFO_FLAG_MACHINE - Apply machine policy rather than user policy
    2014-10-21 11:16:54.065 [pid=0x3e8,tid=0xcd0] ( X ) GPO_INFO_FLAG_BACKGROUND - Background refresh of policy (ok to do slow stuff)
    2014-10-21 11:16:54.065 [pid=0x3e8,tid=0xcd0] ( ) GPO_INFO_FLAG_SLOWLINK - Policy is being applied across a slow link
    2014-10-21 11:16:54.065 [pid=0x3e8,tid=0xcd0] ( ) GPO_INFO_FLAG_VERBOSE - Verbose output to the eventlog
    2014-10-21 11:16:54.065 [pid=0x3e8,tid=0xcd0] ( ) GPO_INFO_FLAG_NOCHANGES - No changes were detected to the Group Policy Objects
    2014-10-21 11:16:54.065 [pid=0x3e8,tid=0xcd0] ( ) GPO_INFO_FLAG_LINKTRANSITION - A change in link speed was detected between previous policy application and current policy application
    2014-10-21 11:16:54.065 [pid=0x3e8,tid=0xcd0] ( ) GPO_INFO_FLAG_LOGRSOP_TRANSITION - A change in RSoP logging was detected between the application of the previous policy and the application of the current policy.
    2014-10-21 11:16:54.065 [pid=0x3e8,tid=0xcd0] ( X ) GPO_INFO_FLAG_FORCED_REFRESH - Forced Refresh is being applied. redo policies.
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] ( ) GPO_INFO_FLAG_SAFEMODE_BOOT - windows safe mode boot flag
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] ( ) GPO_INFO_FLAG_ASYNC_FOREGROUND - Asynchronous foreground refresh of policy
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] Token (computer or user SID): S-1-5-18
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] Abort Flag : Yes (0x313be090)
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] HKey Root : Yes (0x80000002)
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] Deleted GPO List : No
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] Changed GPO List : Yes
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] Asynchronous Processing : Yes
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] Status Callback : No (0x00000000)
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] WMI namespace : Yes (0x32273740)
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] RSoP Status : Yes (0x320cc7f4)
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] Planning Mode Site : (none)
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] Computer Target : No (0x00000000)
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] User Target : No (0x00000000)
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] Calculated list relevance. [SUCCEEDED(S_FALSE)]
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] ----- Changed - 0
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] Options : ( ) GPO_FLAG_DISABLE - This GPO is disabled.
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] ( ) GPO_FLAG_FORCE - Do not override the settings in this GPO with settings in a subsequent GPO.
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] Options (raw) : 0x00000000
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] Version : 19267878 (0x01260126)
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] GPC : LDAP://CN=Machine,CN={GUID-2},CN=Policies,CN=System,DC=SITE,DC=DOMAIN
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] GPT : \\SITE.DOMAIN\sysvol\SITE.DOMAIN\Policies\{GUID-2}\Machine
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] GPO Display Name : Default Domain Policy
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] GPO Name : {GUID-2}
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] GPO Link : ( ) GPLinkUnknown - No link information is available.
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] ( ) GPLinkMachine - The GPO is linked to a computer (local or remote).
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] ( ) GPLinkSite - The GPO is linked to a site.
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] ( X ) GPLinkDomain - The GPO is linked to a domain.
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] ( ) GPLinkOrganizationalUnit - The GPO is linked to an organizational unit.
    2014-10-21 11:16:54.081 [pid=0x3e8,tid=0xcd0] ( ) GP Link Error
    2014-10-21 11:16:54.096 [pid=0x3e8,tid=0xcd0] lParam : 0x00000000
    2014-10-21 11:16:54.096 [pid=0x3e8,tid=0xcd0] Prev GPO : No
    2014-10-21 11:16:54.096 [pid=0x3e8,tid=0xcd0] Next GPO : Yes
    2014-10-21 11:16:54.096 [pid=0x3e8,tid=0xcd0] Extensions : [{00000000-0000-0000-0000-000000000000}{GUID-3}][{GUID-1}{GUID-3}][{GUID-4}{GUID-5}{GUID-6}{GUID-7}{GUID-8}][{GUID-9}{GUID-10}][{GUID-11}{GUID-5}{GUID-6}]
    2014-10-21 11:16:54.096 [pid=0x3e8,tid=0xcd0] lParam2 : 0x3146f978
    2014-10-21 11:16:54.096 [pid=0x3e8,tid=0xcd0] Link : LDAP://DC=SITE,DC=DOMAIN
    2014-10-21 11:16:54.096 [pid=0x3e8,tid=0xcd0] Purge GPH : C:\ProgramData\Microsoft\Group Policy\History\{GUID-2}\Machine\Preferences\Groups\Groups.xml
    2014-10-21 11:16:54.096 [pid=0x3e8,tid=0xcd0] Read GPE XML data file (592 bytes total).
    2014-10-21 11:16:54.112 [pid=0x3e8,tid=0xcd0] ----- Changed - 1
    2014-10-21 11:16:54.112 [pid=0x3e8,tid=0xcd0] Options : ( ) GPO_FLAG_DISABLE - This GPO is disabled.
    2014-10-21 11:16:54.112 [pid=0x3e8,tid=0xcd0] ( ) GPO_FLAG_FORCE - Do not override the settings in this GPO with settings in a subsequent GPO.
    2014-10-21 11:16:54.112 [pid=0x3e8,tid=0xcd0] Options (raw) : 0x00000000
    2014-10-21 11:16:54.112 [pid=0x3e8,tid=0xcd0] Version : 1245203 (0x00130013)
    2014-10-21 11:16:54.112 [pid=0x3e8,tid=0xcd0] GPC : LDAP://CN=Machine,CN={GUID-12},CN=Policies,CN=System,DC=SITE,DC=DOMAIN
    2014-10-21 11:16:54.112 [pid=0x3e8,tid=0xcd0] GPT : \\SITE.DOMAIN\sysvol\SITE.DOMAIN\Policies\{GUID-12}\Machine
    2014-10-21 11:16:54.112 [pid=0x3e8,tid=0xcd0] GPO Display Name : Default Domain Controllers Policy
    2014-10-21 11:16:54.112 [pid=0x3e8,tid=0xcd0] GPO Name : {GUID-12}
    2014-10-21 11:16:54.112 [pid=0x3e8,tid=0xcd0] GPO Link : ( ) GPLinkUnknown - No link information is available.
    2014-10-21 11:16:54.112 [pid=0x3e8,tid=0xcd0] ( ) GPLinkMachine - The GPO is linked to a computer (local or remote).
    2014-10-21 11:16:54.112 [pid=0x3e8,tid=0xcd0] ( ) GPLinkSite - The GPO is linked to a site.
    2014-10-21 11:16:54.112 [pid=0x3e8,tid=0xcd0] ( ) GPLinkDomain - The GPO is linked to a domain.
    2014-10-21 11:16:54.112 [pid=0x3e8,tid=0xcd0] ( X ) GPLinkOrganizationalUnit - The GPO is linked to an organizational unit.
    2014-10-21 11:16:54.112 [pid=0x3e8,tid=0xcd0] ( ) GP Link Error
    2014-10-21 11:16:54.112 [pid=0x3e8,tid=0xcd0] lParam : 0x00000000
    2014-10-21 11:16:54.112 [pid=0x3e8,tid=0xcd0] Prev GPO : Yes
    2014-10-21 11:16:54.112 [pid=0x3e8,tid=0xcd0] Next GPO : No
    2014-10-21 11:16:54.112 [pid=0x3e8,tid=0xcd0] Extensions : [{00000000-0000-0000-0000-000000000000}{GUID-3}][{GUID-1}{GUID-3}][{GUID-9}{GUID-10}]
    2014-10-21 11:16:54.112 [pid=0x3e8,tid=0xcd0] lParam2 : 0x324e8198
    2014-10-21 11:16:54.112 [pid=0x3e8,tid=0xcd0] Link : LDAP://OU=Domain Controllers,DC=SITE,DC=DOMAIN
    2014-10-21 11:16:54.127 [pid=0x3e8,tid=0xcd0] Purge GPH : C:\ProgramData\Microsoft\Group Policy\History\{GUID-12}\Machine\Preferences\Groups\Groups.xml
    2014-10-21 11:16:54.127 [pid=0x3e8,tid=0xcd0] Read GPE XML data file (592 bytes total).
    2014-10-21 11:16:54.143 [pid=0x3e8,tid=0xcd0] Completed get next GPO. [SUCCEEDED(S_FALSE)]
    2014-10-21 11:16:54.143 [pid=0x3e8,tid=0xcd0] WQL : SELECT * FROM RSOP_PolmkrSetting WHERE polmkrBaseCseGuid = "{GUID-1}"
    2014-10-21 11:16:54.143 [pid=0x3e8,tid=0xcd0] Purged 2 old RSoP entries.
    2014-10-21 11:16:54.143 [pid=0x3e8,tid=0xcd0] Logging 2 new RSoP entries.
    2014-10-21 11:16:54.159 [pid=0x3e8,tid=0xcd0] RSoP Entry 0
    2014-10-21 11:16:54.174 [pid=0x3e8,tid=0xcd0] RSoP Entry 1
    2014-10-21 11:16:54.174 [pid=0x3e8,tid=0xcd0] Completed get GPO list. [SUCCEEDED(S_FALSE)]
    2014-10-21 11:16:54.174 [pid=0x3e8,tid=0xcd0] IsRsopPlanningMode() [SUCCEEDED(S_FALSE)]
    2014-10-21 11:17:04.252 [pid=0x3e8,tid=0xcd0] Completed settings update (csePostProcess). [ hr = 0x800700b7 "Cannot create a file when that file already exists." ]
    2014-10-21 11:17:04.252 [pid=0x3e8,tid=0xcd0] Completed CSE post-processing. [ hr = 0x800700b7 "Cannot create a file when that file already exists." ]
    2014-10-21 11:17:04.267 [pid=0x3e8,tid=0xcd0] Leaving ProcessGroupPolicyExLocUsAndGroups() returned 0x000000b7

  • Applying custom Group policy to existing users using group policy

    Hello Everyone,
    i am unable to find a way to push a custom theme to client PC using group policy.
    I have tried "Load a Specific Theme" Group Policy but it is only applying to a new user logging on windows.
    I have a custom theme that i want it to load to every existing user's machine.
    Is there any way to do it using GPO??

    Apply theme group policy does not work. Known issue.
    I use a vb script,
    '@SLH // This Script applies the Themepack "
    On Error Resume Next
    Select Case themeApplied
    Case "yes"
    'Has been set once before, nothing happens!
    Case Else
    'Has not been set before, Company theme is applied
    strRegistryKey = readfromRegistry("HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\General\WallpaperSource", "C:\Windows\web\wallpaper\Windows\img0.jpg")
    End Select
    Function readFromRegistry (strRegistryKey, strDefault )
    Dim WshShell, value
    Set WshShell = CreateObject("WScript.Shell")
    value = WshShell.RegRead( strRegistryKey )
    if strDefault = value then
    'Write key in registry
    WshShell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Themes\themeApplied", "yes", "REG_SZ"
    'Applying theme from server
    'Remember to change the path tothe location of your .themepack file
    WshShell.Run "rundll32.exe %SystemRoot%\system32\shell32.dll,Control_RunDLL %SystemRoot%\system32\desk.cpl desk,@Themes /Action:OpenTheme /file:""\\seraddressto\ Default.themepack"""
    WScript.Sleep 1000
    WshShell.AppActivate("Desktop Properties")
    WshShell.Sendkeys "%{F4}"
    end if
    End Function
    I then run this in a run once script when the user first logs in, this sets the theme once on new profile generation.

  • How to avoid applying Default domain policy?

    Hello! Hope to get some ideas on the following:
    I have one PC that I DO NOT want to apply default domain policy to. I have created a separate OU in AD with one security group, that contains only that one PC.
    I made sure that pc is a member of only that group and not domain computers or any other groups.
    I have created a separate GPO for this PC and linked in to the domain.
    I am seeing in the gpresult /r  that both the new  GPO is applied to the workstation and the default domain gp as well.
    Default domain policy is designed to be applied to all authenticated users.
    I have create a separate user for that workstation that is not a member  of authenticated users.It is only a member of domain users.
    Ultimately I want default domain policy to be filtered out and the gpo specific to this pc to be applied.
    Any ideas?

    > Default domain policy is designed to be applied to all authenticated users.
    >
    > I have create a separate user for that workstation that is not a member
    > of authenticated users.It is only a member of domain users.
    You cannot exclude any computer or user from being an authenticated user...
    > Ultimately I want default domain policy to be filtered out and the gpo
    > specific to this pc to be applied.
    Then simply block inheritance on the OU this computer lives in, and link
    the specific GPO to that OU.
    Martin
    Mal ein
    GUTES Buch über GPOs lesen?
    NO THEY ARE NOT EVIL, if you know what you are doing:
    Good or bad GPOs?
    And if IT bothers me - coke bottle design refreshment :))

  • Applying a service policy on an ACE vlan

    Hi All
    Our ACE is held at a remote site and i just want to apply a Service policy on the client vlan which is also
    our mgmt/access vlan.
    As i am new to ACE s i thought i  would run it past you guyst before i apply it - I am not going to lose
    connectivity to my ACE am i -
    Heres the Service policy -
    policy-map multi-match CLIENT-VIPS
      class VIP-150
        loadbalance vip inservice
        loadbalance policy lb-logic
    class-map match-all VIP-150
      2 match virtual-address xx.xx.xx.150 any
    I was going to apply it  on vlan 121
    int vlan 121
    service-policy input CLIENT-VIPS
    Now the way i read it
    - it should only affect access to the virtual address specified
    Its not going to cut off my access to the ACE by only allowing
    that address through is it ?
    Could be a career damaging move if so for me
    Thanks for your advice
    Steve

    Hello Steve,
    If you are not modifying the MGMT class or policy, you do not need to worry about, like you mentioned, this LB policy is just intended to allow connections to that VIP, nothing else.
    As always it is a good practice to not apply this during production time, as well you can create a test context, where you can test all this without using the production context, so you can play safe and learn at the same time.
    Thanks, hope this help.

  • Windows failed to apply the Group Policy Printers settings

    Windows failed to apply the Group Policy Printers settings. Group Policy Printer
    s settings might have its own log file.
    only when I edit any setting on preferences at computer or users.  
    Ahmed Zidan Network Administrator

    Hi Ahmed,
    >>Windows failed to apply the Group Policy Printers settings. Group Policy Printer
    >>s settings might have its own log file.
    Were we using GPP Printer extension to deploy printers? Did we deploy printers to user accounts or computer accounts? Besides,what printer did we depoly via GPP, local printer, share printer, or TCP/IP printer? Here, we can check event
    logs in Event Viewer to see if more information regarding this issue can be found. Besides, we can also run command
    gpresult/h gpreport.html to further check how group policy settings were applied. If necessary, we can enable GPP Printer debug logging for troubleshooting the issue.
    To enable GPP Printer debug logging, we need to enable the following setting:
    Computer Configuration > Policies > Administrative Templates > System > Group Policy > Logging and Tracing>Configure printer preferences logging and tracing
    Regarding how to enable GPP debug logging, the following article can be referred to for more information.
    Enabling Group Policy Preferences Debug Logging using the RSAT
    http://blogs.technet.com/b/askds/archive/2008/07/18/enabling-group-policy-preferences-debug-logging-using-the-rsat.aspx
    Best regards,
    Frank Shen

  • Applying Domain controller policy to only one DC on a domain

    We want to apply the Microsoft supplied group policy "MSFT Windows Server 2012 R2 Domain controller Baseline" to only 1 out of our 6 Server 2012 R2 Domain controllers. This server is also set-up as an RODC and is in a DMZ
    hence hardening.
    Some of the settings within this policy would seem to be applicable to a domain rather than an individual server (DC), even though they are listed under "Local Policies".
    The following are only some examples, there may be others.......
    Computer Configuration, Policies, Windows Settings, Security Settings, Local Policies/Security Options, Other
    Domain member: Digitally encrypt or sign secure channel data (always)
    Microsoft network server: Digitally sign communications (always)
    Computer Configuration, Policies, Windows Settings, Security Settings, Local Polices/Security Options, Domain Controller
    Domain Controller: LDAP server signing requirements - Require signing
    Computer Configurati......, Local Policies/Security Options, Network Security
    Network Security: Minimum session security for NTLM SSP based (including secure RPC) clients (and Servers) - Require NTLMv2 session security and Require 128-bit encryption
    My question is - If we apply this group policy to one DC only, will it affect any other Domain wide communication e.g. PCs to other DCs, Member servers to other DCs, DCs to DCs etc? I understand that after policy application, the DC may not function
    properly and we will need to test it and potentially relax some of the settings but we cannot afford to risk the rest of the domain from being affected. We are particularly concerned with the forcing of Digitally signing or encypting communications.
    Can anyone help?
    

    If configured incorrectly the policy might disable communication from or to the dc.
    That being said, I think you are pretty safe applying the listed policy items.
    MCP/MCSA/MCTS/MCITP

  • Not getting alerts even after applied the monitoring policy on user defined group.

    Hi,
    recently we have installed OEM Ops center 12c for monitoring our oracle servers. I have created a user defined group and applied a userdefined monitoring policy on that group. I have threshold  70% as crtical and 50 % as warning in my monitoring policy.
    Some of my servers are having 77% disk utlization and im not getting any alerts for that.
    What will be the problem?
    When i see the membership of particular group (group -> membership in center pane), im not able to see the monitoring policy name on the monitoring policy column but i have applied policy on that group.
    Please help me to resolve the issue.
    Thanks,
    Veijar

    Hi Stijn,
    Thanks for the response.
    You are right. I was sending personalized iBot to group 'Financial Analyst'. A non-OBI user(Reshmi) belongs to this group.
    But still problem has not been completely resolved.Still users in group either Administrator/Financial Analyst not getting alert via mail.
    Atleast the users in Administrator group should get alert via mail, since both are defined in rpd.
    Now when i send non-personalized ibot to group 'Financial Analyst', All the users other than Reshmi get alert on their dashboard but they don't get alert
    via mail.Also Reshmi does not get alert via mail and error file shows error like -
    No devices for user: Reshmi.
    Now i am not getting the error nQSError: 43001 Authentication failed for Reshmil in repository Star: invalid user/password. (08004)
    which i was getting earlier while sending personalized ibot.
    I have already defined the Mail tab contents using Job Manager. Also i have selected User Destinations both Interactive Dashboard and Active Delivery
    Profile.
    Why the users don't get alert via mail? What could be the problem?

  • How to apply Software Restriction policy for specific user in local group policy object ?

    I am working on implementing user based software restriction policy programmatically for local group policy object.
    If i create a policy through Domain Controller,i do have option for software restriction policy in user configuration but in local group policy editor i don't have option for that.
    When i look for the changes made by policy applied from Domain Controller in registry, they modifies registry values for specific users on path HKEY_USERS\(SID of User)\Softwares\Policies\Microsoft\Windows\Safer\Codeidentifiers
    They also have registry.pol stored in SYSvol folder in Domain Controller. When i make the same changes in registry to block any other application, application is getting blocked.
    I achieved what i wanted but is it right to modify registry values ?  
    PS:- I am using Igrouppolicyobject API

    I achieved what I wanted but is it right to modify registry values ?
    You also can modify a registry programmatically based policy. Check this:
    http://blogs.msdn.com/b/dsadsi/archive/2009/07/23/working-with-group-policy-objects-programmatically-simple-c-example-illustrating-how-to-modify-a-registry-based-policy.aspx
    We are trying to better understand customer views on social support experience, so your participation in this interview project would be greatly appreciated if you have time. Thanks for helping make community forums a great place.
    Click
    HERE to participate the survey.

  • How do I apply JCE Jurisdiction Policy Files in oracle jvm

         I have some java procedure using AES, while the default key size limit is 128.
         For local java, I can easily replace Jurisdiction Policy Files in JDK OR JRE,  But I do not know how to do such thing in oracle database(11g2) jvm

    $ORACLE_HOME/jdk/jre/lib/security

  • Launch problem opening PSE 13 from a read only desktop applied by group policy

    PSE 13 won't launch.  What is different between opening PSE 13 and other programs? On a normal login it opens. Are there special requirements?

    Hi,
    Thanks for posting your issue in the forum.
    Based on your description, I suspect that maybe Software Restriction Policy has been configured in the domain. At this time, I suggest we could try to collect the following information to narrow
    down the cause of the issue.
    GPMC.log
    ==================
    a. On domain controller, click Start ->Run, type GPMC.MSC, it will load the GPMC console.
    b. Right click on "Group Policy Result" and choose wizard to generate a report for the problematic computer and user account (please place appropriately). (Choose computer and select the proper
    user in the wizard)
    c. Right click 
    the resulting group policy result and click the "Save Report…" => save report to save the report to a HTML file.
    Once we get the report, please check if the Software Restriction Policy has been configured and applied to the problematic computers and users. If so, please disable the policy setting to see
    if the issue persists.
    In addition, please try to refer to the following articles for detailed information about Software Restriction Policy and how to troubleshoot Group Policy problems.
    Software Restriction Policies
    http://technet.microsoft.com/en-us/library/hh831534.aspx
    Troubleshooting Group Policy Problems
    http://technet.microsoft.com/en-us/library/cc787386(v=ws.10).aspx
    Hope this helps.
    Best Regards,
    Andy Qi
    TechNet Subscriber Support
    If you are
    TechNet Subscription user and have any feedback
    on our support quality, please send your feedback here.
    Andy Qi
    TechNet Community Support

  • What is the Best way to apply granular password policy

    I am trying to apply Fine Grain Password Policy in small groups to my users, I have set the password expiry to 10 days
    for testing. But the moment I apply the policy, users start getting password change notifications immediately, Outlook or
    Lync start asking for a new password.
    Should it not wait for 5 days to start poping-up on the clients that they have 5 days left to change there passwords.
    What is the best I can do not to disturb the users, I cannot do this at night because most users have mobile devices. Windows 2012

    Hi Petro,
    In addition to Mihai's answer, also consider checking/changing the 'Interactive logon: Prompt user to change password before expiration' which by default is 14 days. I think there is a default notice period of 5 days but for Windows 7 or 2008 R2
    servers that don't have a Group policy overriding the local policy (not domain joined). I am not sure how that applies to 2012. So if you haven't changed that to 5 days, it might be the cause of the problem.
    On a PSO object I don't think you can set the password change notification.
    The settings can be found in Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\Interactive logon: Prompt user to change password before expiration.
    References:
    http://technet.microsoft.com/en-us/library/jj852243.aspx- Interactive logon: Prompt user to change password before expiration
    http://technet.microsoft.com/en-us/library/cc770842(v=ws.10).aspx - PSO Step Guide
    http://mariusene.wordpress.com/

  • IE10 GPP not applying using Computer Policy

    Hi,
    We're having an issue getting IE10 group policy preferences to apply to our Windows 7 PCs. We set our IE policies based on the OU that the PC is in so we can easily define desktops from laptops, allowing us
    to use a PAC script for laptops so they can connect directly to the internet when not connected to the corporate LAN (none of our laptops have IE10 yet, so I'm not sure if this method has changed as well!).
    We're using a Windows 8 PC to create the policy, but it will not assign to my Windows 7 test PC. The policy is applied to the OU that the PC resides in, so my expectation is that the proxy settings I've configured
    should apply to any user who logs onto that PC.
    Can anyone shed any light on to why this isn't working?
    Thanks in advance.
    Chris

    > to my Windows 7 test PC. The policy is applied to the OU that the PC
    > resides in, so my expectation is that the proxy settings I've configured
    > should apply to any user who logs onto that PC.
    Severe case of misunderstanding :)
    Computers apply computer settings in GPOs that are linked to their OUs.
    Users apply user settings in GPOs that are linked to their OUs. Since
    the GPO is linked to the computer OU, the user doesn't even see it.
    Link it to the user OU and do some Item level targeting to distinguish
    to your needs.
    Martin
    Mal ein
    GUTES Buch über GPOs lesen?
    NO THEY ARE NOT EVIL, if you know what you are doing:
    Good or bad GPOs?
    And if IT bothers me - coke bottle design refreshment :))

Maybe you are looking for

  • How do i delete a thousand pictures from my ipad that were imported from CF card?

    I carried my ipad on trip instead of my laptop, used the ipad to store photos as i filled up my camera's cards.  worked well.  have copied them all the my HD and an external back-up drive.  but, there's seems to be no way to bulk delete all those pho

  • Having Problem with con object

    Can anyone help? I keep getting this error message. cannot resolve symbol symbol : variable con statement stmt = con.createStatement ( ); Here is my code. If you find anything else, please point it out to me. Thanks. import java.sql.*; class mysql {

  • Flash plugin window resize problem

    When i try to resize non-maximized window with this page, firefox not let me do this. I tried on other browsers works fine, but firefox just cancel resize operation and change it's size only on 1-3 pixels. [http://armsenergy.com/as3/forFirefox/index.

  • Oracle Management Server not starting up. says node manager is down!!!

    Hi ALL, We are trying to startup (OMS) Oracle Management Server  but it's not starting up. it tries to connect to the node manager and says failed to connect to Node Manager as the node manager is not running. OPMN also not running. I have attached a

  • MacBook Security

    Can anyone recommend a good program, free or otherwise, that would aid in tracking down or locating my laptop in the event, God forbid, that someone might steal it. TIA